
The Ethereum Foundation announced the launch of Clear Signing, an open standard that aims to replace unreadable transaction prompts with human-readable details before users approve onchain actions. According to reports from the Ethereum Foundation, a working group of wallet developers, security firms and its Trillion Dollar Security Initiative released the standard on May 12. The initiative specifically targets self-custody users and institutions that need readable approval records, addressing what the Foundation describes as a critical security weakness in current transaction approval processes. As reported by Ethereum.org, the Foundation's announcement framed that approval gap as the core problem, noting that even after phishing or infrastructure compromise begins a breach, the final action typically falls to the wallet holder, making this defense the last line of protection. The Foundation called blind signing a "structural flaw" that has contributed to billions of dollars in losses, including the $1.5 billion Bybit hack last year and the $235 million WazirX hack in July 2024. The Foundation emphasized that approvals are often the last defense when users control assets onchain, but when done blindly, that defense does not hold.
Clear Signing utilizes ERC-7730, a shared JSON description format, public registry, and independent reviews to enable wallets to show transaction intentions without changing existing smart contracts or Ethereum settlement processes. As reported by Ethereum.org, a descriptor links contract deployment to readable labels and field formats, allowing compatible wallets to display action details such as asset sent, minimum received, recipient and expiry time instead of raw function selectors and integer values. The Foundation noted that ERC-8176 introduces another standard that allows independent auditors to verify and cryptographically confirm these descriptions are accurate, with wallets deciding which sources to trust based on reputation and audit attestations. Because the system works off-chain, existing apps don't need to change their smart contracts to support Clear Signing. The key components include human-readable transaction descriptions, a neutral, mirrorable descriptor registry, and an attestation framework enabling auditors to verify descriptors. The descriptors themselves live off-chain in a neutral registry at clearsigning.org, which means existing contracts can adopt the standard without needing any redeployment.
Major wallet providers including Ledger, Trezor, MetaMask, WalletConnect and Fireblocks are early supporters of the new ERC-7730 security standard. According to the Ethereum Foundation, Ledger originated ERC-7730 and helped start the standard along with early tooling, while teams including ZKnox, Sourcify, Cyfrin, Zama, WalletConnect, Fireblocks, Trezor, Keycard, MetaMask, Argot and independent contributors participated in the wider development effort. The Foundation stated its security initiative will host the infrastructure and support adoption of the new standard, with Rust and TypeScript libraries funded by the 1TS program hosted on clearsigning.org. Trezor CTO Tomáš Sušánka told Cointelegraph that the company seeks to implement the security feature before June 30, stating it's the right thing to do for users and calling Clear Signing a "critical security advancement for our entire industry." The contributor list reads like every piece of infrastructure that touches Ethereum users today, with Ledger and Trezor on hardware, MetaMask and WalletConnect on software, Fireblocks on institutional custody, Cyfrin on audits and Sourcify and Argot supporting tooling.
The initiative follows the Bybit hack where attackers abused signing screens to approve malicious transfers, with North Korea's Lazarus Group stealing more than $1.5 billion in ETH from Bybit by exploiting Safe Wallet's user interface. As reported by the Ethereum Foundation, Bybit's CEO could not fully verify transaction details before signing, making signing transparency a direct exchange security issue. The Foundation emphasized that approvals are often the last defense when users control assets onchain, but when done blindly, that defense does not hold. The Foundation cited the Bybit incident among recent cases where signed transactions drained user wallets, highlighting how the final step in many crypto exploits is not a software bug but a user approving a transaction. Similarly, in July 2024, the WazirX hack that saw around $235 million stolen from the Indian crypto exchange's multi-sig wallet played out in pretty much the same way. According to Trezor's CTO, attackers have been exploiting this blind signing vulnerability relentlessly, leading users to unknowingly sign malicious smart contracts and lose everything.
Market updates indicate that 22.9 million phishing attempts were blocked in the first quarter of 2026, according to Binance security data, highlighting the prevalence of approval scams. Related coverage reported that crypto protocols lost more than $606 million in the first 18 days of April 2026, marking the worst month since the Bybit breach. While Clear Signing does not remove all attack paths and wallets still choose which registries to trust, it provides users and institutions with clearer visibility of what they are approving before assets move. The release lands as institutions expand their Ethereum footprint, including JPMorgan's recent launch of JLTXX, a tokenized treasury product, with Vitalik Buterin previously flagging transaction transparency as a critical blind spot for the network's next phase of adoption. The timing is strategic, as the Foundation's Trillion Dollar Security Initiative was set up specifically to prepare Ethereum for institutional-scale value that is now sitting directly on-chain. Fireblocks being part of the rollout matters particularly, as it is the custody provider that most traditional finance firms use when they start touching crypto rails. Blind signing was always a tolerable level of risk for retail users moving small amounts, but for asset managers moving real size, it is essentially a non-starter, as you cannot really put a compliance signoff behind a transaction that your operations team isn't able to read in the first place.